Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-754
Weakness type CWE-754 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 95 | 80 | 4 |
Monthly trend
▂▁▁▁▁▁▁▁▂▁▂▁▁▁▂▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▆▃▆█▇▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 1 · 2026-03 1 · 2026-04 0 · 2026-05 16 · 2026-06 5 · 2026-07 16 · 2026-08 22 · 2026-09 18 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-3393 | 8.7 | 98.1 | KEV | PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet |
| CVE-2023-41993 | 8.8 | 97.8 | KEV | Apple Multiple Products |
| CVE-2023-41992 | 7.8 | 95.3 | KEV | Apple Multiple Products |
| CVE-2025-39682 | 9.8 | 86.4 | KEV | tls: fix handling of zero-length records on the rx_list |
| CVE-2026-39929 | 8.7 | 79.4 | — | Lakeside SysTrack Agent LsiAgent.exe Out-of-Bounds Read via UDP |
| CVE-2026-25639 | 7.5 | 77.8 | — | Axios affected by Denial of Service via __proto__ Key in mergeConfig |
| CVE-2026-5946 | 7.5 | 76.4 | — | Invalid handling of CLASS != IN |
| CVE-2024-42284 | 7.8 | 59.0 | — | tipc: Return non-zero value from tipc_udp_addr2str() on error |
| CVE-2026-56812 | 6.3 | 54.9 | — | Phoenix JavaScript presence client crashes on presence keys colliding with Object.proto… |
| CVE-2026-33939 | 7.5 | 53.6 | — | Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation |
| CVE-2026-44324 | 6.5 | 51.4 | — | free5GC: UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interf… |
| CVE-2026-44316 | 7.5 | 49.6 | — | free5GC: PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 40… |
| CVE-2026-44322 | 7.5 | 49.6 | — | free5GC: NEF 3gpp-pfd-management PATCH applications/{appId} panics on UDR access failur… |
| CVE-2026-73314 | 8.7 | 49.4 | — | XenForo < 2.3.13 Signature Verification Bypass via PayPal REST Webhook |
| CVE-2026-69185 | 7.5 | 48.4 | — | Socket.IO: Zero-attachment Memory Exhaustion |
| CVE-2026-0287 | 6.6 | 47.9 | — | PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing |
| CVE-2026-46541 | 7.5 | 47.3 | — | Nimiq network-libp2p: DHT query poisoning via first-record verification failure |
| CVE-2026-73549 | 5.3 | 47.1 | — | Envoy - Incomplete fix for CVE-2026-26310: copyInternetAddressAndPort crashes on scoped… |
| CVE-2026-54775 | 6.5 | 46.8 | — | CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record),… |
| CVE-2026-73430 | 5.3 | 46.7 | — | Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB) |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| linux | 13 |
| 9 | |
| juniper networks | 5 |
| free5gc | 4 |
| indian motorcycle | 4 |
| mattermost | 4 |
| palo alto networks | 3 |
| apple | 2 |
| atn-b1 | 2 |
| eugeny | 2 |
| nimiq | 2 |
| @fastify/busboy | 1 |
| anjvision | 1 |
| axios | 1 |
| corewcf | 1 |